@flarehr/promoted-benefits-admin
Salpac FinOps Admin
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:preact | AI (phantom-deps): Runtime dep consumed via bundled output, not direct import; stable pattern for this Preact-based package. | ai | |
| phantom-deps | phantom-dep:@emotion/css | AI (phantom-deps): Emotion deps used via twin.macro/babel config; not directly imported in source. | ai | |
| phantom-deps | phantom-dep:framer-motion | AI (phantom-deps): Runtime dep bundled into dist; phantom-dep is a false positive for this package. | ai | |
| phantom-deps | phantom-dep:@emotion/cache | AI (phantom-deps): Emotion peer dep; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@emotion/react | AI (phantom-deps): Emotion peer dep; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@emotion/styled | AI (phantom-deps): Emotion peer dep; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:react-hook-form | AI (phantom-deps): Runtime dep bundled into dist; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@heroicons/react | AI (phantom-deps): Runtime dep bundled into dist; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:react-router-dom | AI (phantom-deps): Runtime dep bundled into dist; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@headlessui/react | AI (phantom-deps): Runtime dep bundled into dist; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@tanstack/react-query | AI (phantom-deps): Runtime dep bundled into dist; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:preact-custom-element | AI (phantom-deps): Runtime dep bundled into dist; stable false positive for this package. | ai |
Versions (showing 51 of 420)
| Version | Deps | Published |
|---|---|---|
| 1.4.65534 | 12 / 26 | |
| 1.4.65452 | 12 / 26 | |
| 1.4.65372 | 12 / 26 | |
| 1.4.65229 | 12 / 26 | |
| 1.4.65057 | 12 / 26 | |
| 1.4.64902 | 12 / 26 | |
| 1.4.64746 | 12 / 26 | |
| 1.4.64571 | 12 / 26 | |
| 1.4.64502 | 12 / 26 | |
| 1.4.64431 | 12 / 26 | |
| 1.4.64249 | 12 / 26 | |
| 1.4.64090 | 12 / 26 | |
| 1.4.63903 | 12 / 26 | |
| 1.4.63684 | 12 / 26 | |
| 1.4.63535 | 12 / 26 | |
| 1.4.63464 | 12 / 26 | |
| 1.4.63382 | 12 / 26 | |
| 1.4.63194 | 12 / 26 | |
| 1.4.63026 | 12 / 26 | |
| 1.4.62822 | 12 / 26 | |
| 1.4.62660 | 12 / 26 | |
| 1.4.62464 | 12 / 26 | |
| 1.4.62396 | 12 / 26 | |
| 1.4.62326 | 12 / 26 | |
| 1.4.62092 | 12 / 26 | |
| 1.4.61883 | 12 / 26 | |
| 1.4.61713 | 12 / 26 | |
| 1.4.61557 | 12 / 26 | |
| 1.4.61363 | 12 / 26 | |
| 1.4.61287 | 12 / 26 | |
| 1.4.61211 | 12 / 26 | |
| 1.4.61089 | 12 / 26 | |
| 1.4.60884 | 12 / 26 | |
| 1.4.60700 | 12 / 26 | |
| 1.4.60559 | 12 / 26 | |
| 1.4.60335 | 12 / 26 | |
| 1.4.60269 | 12 / 26 | |
| 1.4.60211 | 12 / 26 | |
| 1.4.60008 | 12 / 26 | |
| 1.4.59848 | 12 / 26 | |
| 1.4.59681 | 12 / 26 | |
| 1.4.59496 | 12 / 26 | |
| 1.4.59350 | 12 / 26 | |
| 1.4.59278 | 12 / 26 | |
| 1.4.59216 | 12 / 26 | |
| 1.4.59042 | 12 / 26 | |
| 1.4.58960 | 12 / 26 | |
| 1.4.58891 | 12 / 26 | |
| 1.4.58729 | 12 / 26 | |
| 1.4.58583 | 12 / 26 | |
| 1.4.58498 | 12 / 26 |
v1.4.65534
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.65452
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.65372
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.65229
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.65057
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.64902
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.64746
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.64571
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.64502
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.64431
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.64249
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.64090
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.63903
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.63684
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.63535
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.63464
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.63382
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.63194
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.63026
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.62822
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.62660
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.62464
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.62396
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.62326
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.62092
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.61883
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.61713
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.61557
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.61363
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.61287
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.61211
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.61089
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.60884
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.60700
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.60559
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.60335
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.60269
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.60211
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.60008
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.59848
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.59681
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.59496
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.59350
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.59278
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.59216
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.59042
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.58960
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.58891
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.58729
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.58583
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.4.58498
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.